T1552.004 Private Keys
Sub-technique of T1552 Unsecured Credentials
Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures.(Citation: Wikipedia Public Key Crypto) Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc. Adversaries…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Cisco Crypto Commandshightest · cisco
- DPAPI Backup Keys And Certificate Export Activity IOChightest · windows
- PowerShell Get-Process LSASShightest · windows
- Certificate Exported Via PowerShellmediumtest · windows
- Certificate Exported Via PowerShell - ScriptBlockmediumtest · windows
- Private Keys Reconnaissance Via CommandLine Toolsmediumtest · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.